logo

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

ID: 560b9a6f-d0d4-5f7d-b7cd-bd679d81482b

STIX ID: report--560b9a6f-d0d4-5f7d-b7cd-bd679d81482b

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

Cisco Talos analyzed msaRAT, a Rust implant deployed prior to Chaos ransomware encryption that spawns a headless Chrome/Edge, uses the Chrome DevTools Protocol to inject JavaScript, and tunnels encrypted C2 over a WebRTC data channel relayed via a Cloudflare Worker and Twilio TURN. The implant is delivered via an MSI masquerading as a Windows update, loads a DLL into memory, and executes commands received through the browser-driven channel; Talos published two network indicators but no file hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.